Four physical-media views are Spun's reason to exist
Spun turns album artwork into a spinning CD, record, cassette, or TP-7-style recorder. The controls follow the object: the vinyl needle seeks, cassette reels move, a disc lid opens, and the recorder wheel can be dragged. Optional 3D bodies add cases, tonearms, lighting, and a small mixer. If those details sound unnecessary, another player will be easier. They are the product here, not decoration around a conventional library screen.
The sources are unusually broad for a new player. Local files stay in place. Cider supplies Apple Music playback and authentication through its local API. Jellyfin, Navidrome, and Subsonic connections provide remote libraries, while anonymous YouTube Music browsing uses an optional Python helper. Each account or source keeps its own queue. That variety is useful, but every path brings different authentication, buffering, permissions, and failure modes.
Source-only installation needs Qt 6.8 and TagLib 2.0
There is no packaged installer or GitHub release. Arch, CachyOS, and Fedora get explicit dependency commands, while Nix users have a flake. The general build requires a C++20 compiler, CMake 3.22 or newer, Ninja, Qt 6.8 or newer, and TagLib 2.0 or newer. Qt Quick 3D is optional and can be disabled if the visual models are not worth the extra dependency.
Ubuntu is the awkward case. The README says the default repositories in 22.04 and 24.04 do not supply new enough Qt or TagLib packages, so users must install a newer Qt SDK and build TagLib separately. That is substantial setup for a music player. The launcher also points back to the cloned folder, which means moving the source requires reinstalling the launcher entry.
What happened when we ran it
Our sandbox tested commit d4448ec in the helper/ directory, not the C++ desktop app. The Python installation took 18 seconds, added 42 packages, and used 64 MB on disk. Its build check succeeded in 6 seconds. The Debian container had 3 CPUs, 8 GB of RAM, no secrets, and no elevated privileges. Pip-audit reported 0 known vulnerabilities.
The test command failed with exit code 5 after 6 seconds. Pytest reported no tests ran in 0.00s, which means 0 passed and 0 failed because it collected 0 tests. The repository does contain a tests directory, but there was no Python test for this helper path. Calling that a product regression would be wrong. Calling it a green test run would be wrong too.
The checkout contained 200 files, roughly 21,951 lines of source, and 5.8 MB before helper dependencies. Our scan found no CI workflow and no Dockerfile. The main CMake project registers native tests when built with testing enabled, but those checks need the Qt toolchain and, depending on the case, a display, audio session, D-Bus, or disposable Jellyfin and Navidrome servers. We did not run them.
Every music source carries a different boundary
Cider must remain running for Apple Music, and its local API needs separate approval for search and queue access. Spun says it does not ask for the Apple Music password. Jellyfin tokens can go into the desktop keyring, while Subsonic uses salted token authentication and may store a remembered password there. Remote servers should use HTTPS. These are reasonable choices, but the desktop keyring and server permissions become part of setup.
The YouTube route is unofficial and depends on ytmusicapi plus yt-dlp. It has no Google login or account synchronization, and its local favorites and history stay on the device. Network or YouTube changes can break playback until those dependencies catch up. Our 42-package helper install is the measured cost of that optional path; local files and Cider do not require it.
The license rules out ordinary commercial adoption
Spun uses PolyForm Noncommercial 1.0.0 for its original code and assets. The README explicitly calls it source-available and says the license is not OSI approved. Personal use and the other listed noncommercial or institutional cases are permitted under the license terms. A company that wants to bundle, sell, or operate it should not assume the visible source grants the same rights as MIT, Apache, or GPL software.
Project health is active but brief. GitHub showed 434 stars, 20 combined issues and pull requests, and a last push on September 16, 2026. A Fedora user reported a crash after enabling 3D, and issue 5 still asks for CI. Pull-request activity continued through September 23, including distribution setup work. Test the 2D player first, then enable 3D on your actual graphics stack. The simulated hardware is Spun's best reason to accept the source build, and also the part most likely to expose driver differences.

